0% found this document useful (0 votes)
3 views40 pages

1.risk Management Process Cycle

The document outlines the process of risk management, emphasizing the importance of risk identification, analysis, evaluation, and treatment within organizations. It details various types of risks, including commercial, financial, directional, and environmental risks, as well as methods for identifying and assessing these risks. Additionally, it highlights the significance of stakeholder involvement, the use of risk registers, and the necessity of continuous monitoring and reporting to effectively manage risks.

Uploaded by

amulenga92
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PPTX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
3 views40 pages

1.risk Management Process Cycle

The document outlines the process of risk management, emphasizing the importance of risk identification, analysis, evaluation, and treatment within organizations. It details various types of risks, including commercial, financial, directional, and environmental risks, as well as methods for identifying and assessing these risks. Additionally, it highlights the significance of stakeholder involvement, the use of risk registers, and the necessity of continuous monitoring and reporting to effectively manage risks.

Uploaded by

amulenga92
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PPTX, PDF, TXT or read online on Scribd

Risks Management

Process/cycle
UNIT 8
Session learning objectives
• After completing this session you should be able to:
• Evaluate the impact of risks upon an organisation
• Link various stages into a risk identification process
• Methods for identifying ,assessing and quantifying risks.
Introduction
• Risk identification is a deliberate and systematic effort to identify and document
the Institution’s key risks. The objective of risk identification is to understand
what is at risk within the context of the Institution’s explicit and implicit objectives
and to generate a comprehensive inventory of risks based on the threats and
events that might prevent, degrade, delay or enhance the achievement of the
objectives.
• This necessitated the development of risk identification guidelines to ensure
that Institutions manage risk effectively and efficiently. Modern-day businesses
face various risks to their day-to-day operations. For example, a company’s
network may be hacked, compromising employee, and customer data. Natural
disasters such as hurricanes, tornadoes, and wildfires can also impact an
organization’s ability to operate.
• Ensuring the safety of a company and its employees is about more than being
able to react quickly to a threat. Effective risk management involves preparing
for a threat before it happens.
Risk management Process
[Link] Identification
[Link] analysis /Assessment(Evaluating)
3. Risk Treatment/Risk Strategies
[Link] Monitoring And Reporting
Risk Management process which is constituted of two main elements:
• Risk Analysis and Risk Control
• Risk Analysis process covers the identification, estimation and
evaluation of risk. Proper implementation of all stages in this process
will result in the recognition of potential risk events affecting supply
chain. The term risk assessment is also interchangeably used in
referring to risk analysis.
• Risk Control looks at how risks can be controlled and the strategies
that an organisation can adopt to control risk not all risk events fall
under the category of disruption risk events, and therefore the
potential impact caused by an individual risk event needs to be
carefully.
[Link] Identification
• Risk identification should be inclusive, not overly rely on the inputs of a few
senior officials and should also draw as much as possible on unbiased
independent sources, including the perspectives of important stakeholders.
• A stake holder is someone who has vested interest in what an organisation is
doing. Identifying potential risks:
• In this step, the project team and stakeholder identify potential risks that
could impact the project. This includes internal factors, such as resource
shortages, and external factors, such as changes in regulations or market
conditions.
• The risk identification process defines the scope of a project or program. It
consists of various steps outlining the project’s boundaries and requirements.
Also, this ensures that it considers and accounts for all potential risks. These
stages include:
The following are key steps necessary to effectively identify risks
from across the Institution:
1. Understand what to consider when identifying risks
2. Gather information from different sources to identify risks
[Link] risk identification tools and techniques
[Link] the risks
5. Document the risk identification process
[Link] the effectiveness of the risk identification process.
Classification of risks in a business
-Commercial risk-commercial risk can come from an number of areas including
• volatiles market places
• material costs
• selection of supply chain partners
• failure of business
• underperformances in the supply.
• Lack of knowledge of new markets or products and poor board direction often serve to exacerbate
these risks.
-Financial risks- Cash flow, Capital funding, Credit rating etc
-Directional risks-This simply means an organisation may select a direction that is the wrong one
or at least, it may turn out to be the wrong one. An example ,a company or business may set up to
dominate a market ,by acquiring some competitors and driving others out of the business by
aggressive pricing techniques
-Environmental risks- These are risk that encompasses changes to environmental legislation
such as the waste or pertain to changes in the [Link] could even cover where residential
housing is built right up to a factory s perimeter thus altering the altering the factory environment
awareness needs
Environmental risks
1. Governmental regulatory concerns
2. Changes in exchange rates
3. Rapid changes in technology
4. Competition risk
5. Insufficient public utility supply
External sources of Risks

Whether we aim at personal life objectives or workplace goals and


objectives ,things that occur in the wider world are bound to affect
our ability to succeed.
• External influences can affect the success of an organizations
objectives.
• World issues(Covid 19 issues, wars, Famine etc.)
• International issues(Trade barriers,Embargo,tarrifs etc.)
• National issues (government policies)
• Local situation
Sources of Risk

• Sources of risk in an organisation can emanate from both inside and outside an
organisation.
• Risks can be created through the selection and adoption of certain strategies, tactics
and projects in an organisation.
• Risk in an organisation can be created through the following
[Link] level
[Link] level
[Link] level
• Focus points of risk identification To ensure comprehensiveness of risk identification
the Institution should identify risk factors through considering both internal and
external factors, through appropriate processes.
Risk identification
• Risk identification enumerates all types of risks in the supply
chain.
Common risk identification methods include
• Delphi method, checklists
• Module decomposition method and scenario analysis
(presented a conceptual model for identifying and assessing
supply chain risks.
• Scenario planning in proactive management of supply chain
risks.
[Link] risk identification
• Strategic risk identification to identify risks emanating from the strategic
choices made by the Institution, specifically with regard to whether such choices
weaken or strengthen the Institution's ability to execute its Constitutional
mandate:
• Strategic risk identification should precede the finalization of strategic choices to
ensure that potential risk issues are factored into the decision making process
for selecting the strategic options.
• Risks inherent to the selected strategic choices should be documented,
assessed and managed through the normal functioning of the system of risk
management; and strategic risks should be formally reviewed concurrently with
changes in strategy, or at least once a year to consider new and emerging risks.
Risks created at strategic level can in form of the following
[Link]
[Link]
3. Acquisition of other business
• Strategic risk management is based around alternative courses of action which an
organisation may take to minimize the effects of potential risks which may detract ,or
even prevent the strategy being achieved.
• The risks could affect the continuing survival of the organisation.
• An organisation strategy implements the vision and mission of organisation founders
or its highest management level .
• The strategy flows down into objectives which will be achieved by applying resources
–Money, Manpower, Machinery together with appropriate skills and knowledge.
[Link] risk
• Operational risk identification to identify risks concerned with the Institution’s
operations: Operational risk manifests itself at a lower level in the management of
the organisation can threaten business survival. An example can be failure to
manage debtors and cash flow can quickly and lead to bankruptcy
• Operational risk identification should seek to establish vulnerabilities introduced by
the following :
• Employees
• Internal processes and systems,
• Contractors
• Regulatory authorities and external events.
• Operational risk identification should be an embedded continuous
process to identify new and emerging risks and consider shifts in
known risks through mechanisms such as:
• Management and committee meetings
• Environmental scanning
• Process reviews and the like.
• Operational risk identification should be repeated when changes
occur, or at least once a year, to identify new and emerging risks.
Advantages of risk identification
• Early identification of potential risks.
• Improved planning and preparation for potential risks.
• A better understanding of the risks involved in a project.
• Improved communication and collaboration among stakeholders.
Disadvantages
• Time and resource consumption.
• Difficulty in accurately predicting all risks.
• Potential for over-analyzing risks and losing focus on the project’s
objectives.
2. Risk Analysis
Risk analysis is the procedure of analyzing and recognizing any kind of risk that could
adversely affect the primary business objective or any critical projects that are about to take
place in an organization in regards to avoiding or to take necessary initiatives to reduce such
risks in the organization.
Risk Analysis is a process that helps you to identify and manage potential problems that could
undermine key business initiatives or projects. However, it can also be applied to other
projects outside of business, such as organizing events or even buying a home!
Risk is made up of two parts: the probability of something going wrong, and the
negative consequences if it does.
Risk can be hard to spot sometimes an organisation can be hit by a consequence that didn’t
planned for, costs, time, and reputations could be on the line. Similarly, overestimating or
overreacting to risks can create panic, and do more harm than good.
 This makes Risk Analysis an essential tool.
 It can help you to identify and understand the risks that you could face in your role.
 It can helps to manage these risks and minimize their impact on an organisation plans.
Assessing the likelihood and impact:
• Once potential risks have been identified, the next step is to assess the
likelihood and impact of each risk. The likelihood refers to the probability of the
risk occurring, while the impact refers to the potential consequences if the risk
does occur.
Prioritizing risks:
• Based on the likelihood and impact of each risk, the risks should be prioritized so
that the most critical risks can be addressed first. This ensures that the project’s
limited resources go toward the most important risks.
Developing risk mitigation plans:
• For the most critical risks, the project team should develop risk mitigation plans
to minimize the potential impact of the risks. Hence, this may include purchasing
insurance, making changes to the project schedule, or developing contingency
plans.
How and why the risk can happen (i.e. causes and consequences).
• The existing internal controls that may reduce the likelihood or
consequences of the [Link] is essential when identifying a risk to
consider the following three elements:
[Link]/event - an occurrence or a particular set of
circumstances
2 .Causes - the factors that may contribute to a risk occurring or
increase
[Link] likelihood of a risk occurring and consequences and the
outcome(s) or impact(s) of an event.
• It is the combination of these elements that make up a risk and this level
of detail will enable an Institution to better understand its risks.
Carrying out a Risk Analysis
• To carry out a Risk Analysis,
1. Identify the possible threats that you face,
2. Estimate their likely impacts if they were to happen
3. Estimate the likelihood that these threats will materialize.
• Risk Analysis can be complex, as you'll need to draw on detailed information such as
project plans, financial data, security protocols, marketing forecasts, and other
relevant information.
• However, it's an essential planning tool, and one that could save time, money, and
reputations.
Use of Risk registers
• The document in which the risks are recorded is known as the "risk register"
and it is the main output of a risk identification exercise.
• A risk register is a comprehensive record of all risks across the
Institution or project depending on the purpose/context of the register.
• There is no single blueprint for the format of a risk register and Institutions
have a great degree of flexibility regarding how they lay out their documents.
• The risk register serves three main purposes:
1. It is a source of information to report the key risks throughout the Institution,
as well as to key stakeholders
[Link] uses the risk register helps to focus their priorities risks.
3. It is to help the auditors to focus their plans on the Institution's top risks
The risks register records:
• Risk category- how and why the risk can happen "cause of risk.
• How will the risk impact the Institution if it materializes "impact on
Institution.
The qualitative and or quantitative cost should the risk materialize.
The likelihood and consequences of the risk to the Institution.
• The existing internal controls that may minimize the likelihood of the risk
occurring.
• A risk level rating based on pre-established criteria.
• Framework, including an assessment of whether the risk is acceptable or
whether it needs to be treated.
• A clear prioritization of risks (risk profile).
Process of Risk Analysis
• Analyzing risk in a project can have both a positive and negative effect. Such
effects can have both worldly and non-materialistic impacts on the
organization.
• A risk is an uncertain event that can have both positive and negative effects.
• Analysing the Risk
After identifying risk, it’s likely to understand and assess the extent of risk
and nature of risk that most likely to happen and to what extent it may occur
to the organization shall be analyzed.
• Risk analysis can be done in two ways. Quantitative and qualitative analysis
are the two approaches to risk analysis.
• Qualitative analysis
• Quantitative analysis
1. Quantitative Risk Analysis
• Quantitative risk analysis looks at the effect of the potential project risk that can be
there on the target of the project is evaluated numerically.
• The primary purpose of the Quantitative analysis is to quantify the risk exposure
and determine the size of the cost and the schedule contingencies.
2. Qualitative Risk Analysis
• Qualitative risk analysis, looks at the probability and impact of the potential project
risk that can be there on the target of the project is evaluated against a predefined
scale. It is a subjective approach.
• The primary purpose of qualitative risk analysis is to increase awareness of the
severe risk and creating risk responses to deal with and reduce the effect of these
risks on the overall project.
Methods of Risk Analysis
• Methods of Risk analysis include both Qualitative and Quantitative application
techniques. Most projects shall apply Quantitative analysis in measuring risk, which is
overlooked in terms of formal qualitative risks.
Useful qualitative risk analysis considered to be involved in project management.
• Delphi Technique – Delphi Technique uses expert opinion to identify, analyze, and
evaluate risks on an individual and anonymous basis.
• SWIFT Analysis – In SWIFT analysis, the team investigates how changes are
approved, designed, or planned that might affect the project in any way. It is a
systematic team-based approach.
• Decision Tree Analysis – This analysis is done by proposed decisions and finding
different pathways and results due to the proposed findings.
• After all the probabilities are analyzed, the course of action of modifying and verifying
When to Use Risk Analysis
Risk analysis is useful in many situations:
• When planning projects, to help you to anticipate and neutralize
possible problems.
• When deciding whether or not to move forward with a project.
• When improving safety and managing potential risks in the workplace.
• When preparing for events such as equipment or technology failure,
theft, staff sickness, or natural disasters.
• When planning for changes in your environment, such as new
competitors coming into the market, or changes to government policy.
Difference Between Risk Identification And Risk
Assessment
Risk Identification Risk Assessment

The first step in the risk management process. The next step after risk identification.

Involves identifying potential risks. Involves evaluating the impact of identified risks.

Focuses on the likelihood of risks occurring. Focuses on the consequences of risks occurring.
Risk Matrix Example
Impact/Likelihood Low Medium High

High Impact Medium High Extreme

Medium Impact Low Medium High

Low Impact Low Low Medium


3. Risk evaluation
• Evaluating the Risk
Analyzing risk helps you to estimate the capacity of risk that may
happen. Hence in evaluating the risk, the team shall rank the calculated
risk to decide whether to accept such risk or not.
• Risk evaluation attempts to define what the estimated risk actually
means to people concerned with or affected by the risk.
• Risk evaluation involves comparing the results of the risk analysis with
the established risk criteria to determine where additional action is
required.

• A large part of this evaluation will be the consideration of how
people perceive risks. The complex process of determining the
significance or value of the identified hazards and estimated risks
to those concerned, or affected, is examined.
• The evaluation of risk is concerned with issues relating to how
those affected by risks perceive them, the value issues underlying
the perceived problem and the trade-off between the perceived
risks and benefits.
• This looks at the factors involved in risk perception and risk
acceptance.
Importance of risk evaluation and perception
• Risk evaluation attempts to define what the estimated risk actually
means to people concerned with or affected by the risk.
• A large part of this evaluation will be the consideration of how people
perceive risks.
Risk Treatment
• Risk treatment involves developing a range of options for mitigating the risk,
assessing those options, and then preparing and implementing action plans.
• Risk treatment is a collective term for all the tactics, options, and strategies
chosen to respond to a specific risk, bound to achieve the desired outcome
concerning the threat.
• Risk treatment: The plan of implementing various strategies, activities, and
actions to appropriately deal with the threat and manage it in a possibly
profitable [Link] highest rated risks should be addressed as a matter of
urgency.
• Selecting the most appropriate risk treatment means balancing the costs of
implementing each activity against the benefits derived. In general, the cost
of managing the risks needs to be commensurate with the benefits obtained.
When making cost versus benefit judgements the wider context should also
be taken into account
• Risk strategy-should complement other corporate strategies and be
related to the objectives flowing from all the other corporates activities.
• Risk strategy revolve around the key words avoid,reduce,minimise
share and accept .
• The generic strategies that have been developed as the 4T’s because
each strategy begins with the letter T.
• The strategies are:
[Link]
[Link]
[Link]
[Link]
Treatment of risk
• Treating means to manage the risks actively and thereby recognizing the probability of it
occurring and the effect it may have on the organisation .
• Treating (Reduce) -The risk will rarely reduce it to zero, despite any mitigation action
taken, it will simply bring the risk down to levels deemed as acceptable.(The risk which
remains after being managed is called residual risk).
• Tolerating (Accept)- The risk has been recognised and has either been managed down
to acceptable levels .This risk maybe be remote, small or minor a possibility that it is not
worth the time, money or effort involved in doing something about it.
• Transferring (Share)-The risk after been identified, it has been resolved by giving it to
someone else to manage. Insurance and outsourcing is a good example of risk transfer.
Part transfer may occur as a means of treating a risk and means sharing part of the risk
with a third party as might occur in a joint venture.
• Terminating (Avoid)-A risk means that having recognised a risk, whatever action maybe
taken to manage it, it is simply too risky to continue oh perhaps too expensive to
manage. In relation to the rewards which might be available.
Develop a risk treatment plan
• Determine the level of treatment plans required for each risk level. For example, for risks rated as ‘high', a
treatment plan must be developed. However for risks rated as ‘low' and ‘very low' that have improvement
opportunities, development of a treatment plan may be at the discretion of the partner or partners.
• Effective risk treatment relies on attaining commitment from key practice stakeholders and developing
realistic objectives and timelines for implementation.
• For each risk identified in the risk assessment, detail the following:
• Specify the treatment option agreed - avoid, reduce, share/transfer or accept.
• Document the treatment plan - outline the approach to be used to treat the risk. Any relationships or
interdependencies with other risks should also be highlighted.
• Assign an appropriate owner - who is accountable for monitoring and reporting on progress of the
treatment plan implementation. Where the treatment plan owner and the risk owner are different, the risk
owner has ultimate accountability for ensuring the agreed treatment plan is implemented.
• Specify a target resolution date - where risk treatments have long lead times, consider the development of
interim measures. For example, it is unlikely to be acceptable for a residual risk to be rated ‘high' and to have
a risk treatment with a resolution timeframe of two years.
[Link] Monitoring and Mitigation

• Once areas of risk have been identified, an organization needs to monitor their internal and
external environment. This helps them to predict when risky events are becoming more likely.
It also helps to identify new risks and is tightly linked to the best practice of Supply Chain Risk
Identification.
• Risk monitoring: The implementation of a continuous control system over the threat after
treating it.
• Risk mitigation comprises all the actions that can help to prevent the risk occurring or reduce
the impact or costs of such risks. Risk mitigation will lead to a more secure business
environment and even a safer working environment if we apply it to healthy and safety issues.
• In terms of quality, the implementation of quality assurance techniques and procedures is
a way of mitigating the risk of substandard product or service. By building quality into a
product, service or process, we are clearly reducing the chances that something will go wrong
and lead to loss, damage or injury
Set timelines
• You need to set timelines and deadlines for ensuring risks are managed and treated. Make sure the most
urgent risks are dealt with first.
• Write down when things need to be checked and tick them off your risk register when they've been
complete Keep records
• It's important that you investigate and record any accidents or near-misses. This will provide you with a
document trail in case you need to justify your actions, but it will also help you to avoid similar incidents
happening again.
• Investigate the incident - what went wrong? Why? What could have prevented it? Document the details of
the incident and the answers to those questions for future reference. And act on the information.
• Records you should keep include:
• Minutes of meetings - noting important decisions and the reasons for them
• File notes - a record of important conversations in person or on the phone
• Training records - documenting any training undertaken by staff or volunteers
• Incident records - notes taken or forms completed in the event of any injury or incident.
Risk categories

General risks
• Reputational – Loss of customer or employee confidence, or damage to market
reputation.
• Procedural – Failures of accountability, internal systems, or controls, or from fraud.
• Project – Going over budget, taking too long on key tasks, or experiencing issues
with product or service quality.
• Financial – Business failure, stock market fluctuations, interest rate changes, or
non-availability of funding.
• Technical – Advances in technology, or from technical failure.
• Natural – Weather, natural disasters, or disease.
• Political – Changes in tax, public opinion, government policy, or foreign influence.
Summary

• Documenting the risk identification process is important as documenting identified


risks. It is also necessary to document the risk identification process to help guide future
risk identification exercises and to ensure good practices are maintained by drawing on
lessons learned through previous exercises.
Documentation of this step should include:
• The approach or method used for identifying risks
• The scope covered by the identification; and the participants in the risk identification
and the information sources consulted.
• Experience has shown that management often disregards well controlled risks when
documenting the risk profile of the Institution.
• It is stressed that a well-controlled risk must still be recorded in the risk profile of the
Institution. The reason for this logic is that the processes for identifying risks should
ignore at that point any mitigating factors (these will be considered when the risk is being
assessed).

You might also like